15027Third-party advisory
http://secunia.com/advisories/15027 CVE-2005-1233
PHP Labs - '.proFile' Dir URI Cross-Site Scripting
Record summary
CVE-2005-1233 has a selected CVSS score of 4.3; EIP currently links 2 catalogued exploits.
Description
Cross-site scripting (XSS) vulnerability in index.php in PHP Labs proFile allows remote attackers to inject arbitrary web script or HTML via the (1) dir or (2) file parameters.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBPHP Labs - '.proFile' Dir URI Cross-Site ScriptingExploitDB exploitby sNKenjoiNot analyzed1 file
ExploitDBPHP Labs - '.proFile' File URI Cross-Site ScriptingExploitDB exploitby sNKenjoiNot analyzed1 file
References
91013756vdb entry
http://securitytracker.com/id?1013756 15697vdb entry
http://www.osvdb.org/15697 13276vdb entry
http://www.securityfocus.com/bid/13276 13282vdb entry
http://www.securityfocus.com/bid/13282 snkenjoi.com
http://www.snkenjoi.com/secadv/secadv7.txt ADV-2005-0370vdb entry
http://www.vupen.com/english/advisories/2005/0370 profile-indexphp-xss(20169)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/20169 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2005-1233